WordPress 插件 Spectra Legacy – Gutenberg Blocks 在所有 2.20.0 及以下版本中存在敏感信息泄露漏洞。该漏洞通过 函数导致安全问题,该函数在未进行权限检查的情况下,通过 对象暴露了 配置项。这使得拥有 Contributor 级别或更高权限的攻击者能够提取管理员配置的原始 Instagram Graph API 访问令牌等敏感数据。要利用此漏洞,必须同时启用 Spectra Pro 插件并关联一个 Instagram 账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| brainstormforce | Spectra Legacy – Gutenberg Blocks | ≤ 2.20.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| brainstormforce | Spectra Legacy – Gutenberg Blocks | 0 ~ 2.20.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet